← All articles

Researchers escape OpenAI Codex sandbox to run commands on developer machines

Accomplish AI researcher Oren Yomtov disclosed two OpenAI Codex sandbox escapes, the more serious dubbed Heapjack. Codex Desktop installs a node_repl component into the global config with no opt-in, and plain Codex CLI users inherit it. That process runs trusted OpenAI code and untrusted agent code in one Node instance sharing a heap, where a random authorization token sits in memory. Untrusted code snapshots the heap, recovers the token, and writes requests onto the pipe to an unsandboxed parent process, reaching any Unix socket including a Docker daemon. Opening a malicious repository and asking about the code yields unsandboxed execution with no prompt.

Check
Update Codex CLI and Desktop to the fixed builds, then review whether developers opened untrusted repositories in Codex during the exposure window.
Affected
Any Codex user, including CLI users who never enabled it, could be handed host command execution by opening someone else's repository and querying it.
Fix
Apply OpenAI's patches, isolate coding agents from Docker sockets and credentials, and treat opening untrusted repositories in an agent as code execution.